
RedTiger Stealer: GoFile + Discord-Webhook Exfiltration
A single-host smash-and-grab infostealer intrusion. An artist ran a PyInstaller-compiled executable disguised as a Roblox FPS-unlocker mod that was actually the open-source RedTiger stealer. In one short burst it unpacked to Temp, blackholed security-vendor domains in the hosts file, persisted via the Startup folder, injected JavaScript into the Discord client, and archived Discord tokens, browser credentials and cards, a crypto wallet, a webcam frame, and a screenshot. Exfiltration ran in two stages over legitimate cloud: the loot ZIP was uploaded to GoFile, then the download link plus victim recon was posted to a Discord webhook. Reconstruct the kill chain from SIEM, endpoint XDR, and perimeter firewall telemetry, and classify the key ATT&CK techniques.
Start this operation
Investigation Tasks
Complete each task by investigating alerts and submitting your findings.
Incident brief
0Orient yourself before pivoting into the data. This is a no-answer briefing checkpoint.
Find the initial payload
40Every later event traces back to one execution on one workstation. Identify the file the artist was tricked into running.
Classify the defense-evasion step
35Before stealing anything, the payload tried to blind the host's security tooling. Classify what it did.
Pin the persistence artifact
40The stealer arranged to come back at the next logon. Provide the full path it planted to survive a reboot.
Trace stage one of the exfiltration
40The stolen data left the network first. Identify the anonymous cloud-storage host that received the loot archive.
Recover the operator's notification channel
40Stage two told the operator where to grab the loot. Recover the exact channel the link was sent to.
Classify the exfiltration technique
35Name how the stolen data was carried off the network. Classify the exfiltration technique the archive upload used.
7 tasks · 230 points total
Training Tools
Skills You'll Build
Requires foundational alert triage skills. Multiple data sources to correlate.
Prerequisites
- Basic understanding of security alerts
- Familiarity with XDR concepts
- Familiarity with SIEM concepts
- Familiarity with Firewall concepts
Ready to investigate?
More Operations
View allConsent Granted: Malicious OAuth App Mailbox BEC
A consent-phishing intrusion where an adversary-in-the-middle proxy steals a finance analyst's Microsoft 365 session, then the attacker tricks her into granting a malicious multitenant OAuth application delegated mailbox permissions. The app gets its own client secret for durable access, reads her mailbox over Microsoft Graph, hides vendor replies with an inbox rule, and sends a fraudulent bank-detail-change reply into a live settlement thread. Work the Entra consent and permission-grant audit, the service-principal credential change, the Graph mailbox operations, and the email evidence to reconstruct the chain.
RapperBot: From SSH Brute-Force to DDoS and Hidden XMRig Mining
A Mirai-derived DDoS botnet brute-forces SSH on an internet-exposed Linux edge gateway, persists an attacker SSH key in root's authorized_keys, pulls a Bash stager, and drops a single merged binary that fuses the RapperBot DDoS client with an embedded XMRig Monero miner. The bot registers with a hardcoded C2 over a custom binary protocol, floods an external victim with UDP/TCP/HTTP traffic, and quietly mines Monero through two proxy pools hosted on the C2 IP itself. Reconstruct the chain from SIEM, endpoint XDR, and perimeter firewall telemetry.
Hidden in the Pixels: LSB Steganography Exfil From an Infected Endpoint
A LummaC2/Vidar-style infostealer smash-and-grab. A finance analyst was tricked by a fake CAPTCHA (ClickFix) into pasting an mshta command into the Run box, which staged hidden PowerShell, downloaded the Lumma stealer, and harvested browser credentials, cookies, and wallet artifacts. To smuggle the loot out, the operator LSB-encoded the stolen blob into an oversized PNG and uploaded it to a public image host, off the command-and-control channel. Reconstruct the chain from SIEM and perimeter firewall telemetry and classify the key ATT&CK techniques.